Security & Data Handling

Last updated: October 9, 2026

Vero is an AI health assistant operated by Senddy, Inc. This page explains how we protect health information — in plain language that users, clinicians, and AI answer engines can cite. For common questions in short form, see the FAQ. For the full legal terms, see our Privacy Policy.

1. Who operates Vero

Vero is the product name. The legal operator is Senddy, Inc., which also lists Vero on the Apple App Store. Senddy, Inc. is the entity responsible for the app, website at heyvero.ai, and related services.

2. What Vero is — and is not

Vero helps you organize labs, wearables (via Apple Health), medications, nutrition, and health history, and explains them in the context of your own data. It is an educational tool and organizer — not a medical device, and it should not be used as the sole basis for diagnosis, treatment decisions, or emergency care. Always consult a qualified clinician for medical judgment.

3. Encryption

We protect health data with layered encryption, and we encrypt by sensitivity rather than by table. Your conversations with Vero, your notes, and your lab documents are encrypted on your device before they sync. Structured health data (medications, conditions, allergies, food log) is protected by row-level access control and encrypted at rest and in transit.

What's encrypted where

Encrypted on your device before sync

  • Your conversations with Vero, and their titles
  • Notes you write on meds, conditions, food and doses
  • Lab documents and photos, their extracted text and summaries, and the provider and patient names on them
  • What Vero remembers about you
  • Your date of birth

Access-controlled, encrypted at rest and in transit

  • Medications, dosages, schedules and dose history
  • Conditions, allergies and family history
  • Food log and meal plans
  • Body metrics and goals (height, weight, activity level)
  • Your display name and lab test types

Structured data is readable by our servers so that features that need it — refill and adherence reminders, caregiver alerts, lab trends over time — can actually work. Access is scoped per user by database policy: one account can never read another's rows.

  • Encryption in transit: all traffic uses TLS (HTTPS).
  • Encryption at rest: stored health data uses AES-256 encryption.
  • Key escrow: encryption keys are wrapped and escrowed so that a database dump alone is not sufficient to read user health data.

What we do not claim: Vero is not zero-knowledge end-to-end encryption across every feature. AI features require plaintext context at inference time (see below), so a blanket "end-to-end encrypted app" claim would be inaccurate.

Updated September 2026.

4. AI providers (OpenRouter, OpenAI & Google)

When you use AI features (chat, lab analysis, and related insights), and after you grant in-app permission, selected context — such as your messages, uploaded files or images, profile details, lab summaries, and authorized HealthKit context — may be sent through our servers and OpenRouter to the AI provider that answers the request, currently OpenAI or Google, to generate responses.

  • This means health data used for AI analysis is not remaining solely on your phone while those features run.
  • No model training on your health data: Senddy does not use identifiable user health data to train Vero models. Under our provider agreements and configured API services, OpenRouter, OpenAI and Google do not use submitted Vero data to train their general-purpose models.
  • De-identification where the feature allows: when possible, we remove or replace direct account identifiers (such as name or email) before sending context for AI processing. Some requests require personal health context to answer and therefore cannot be fully de-identified.
  • We have Business Associate Agreements (BAAs) in place with applicable providers where required.
  • We do not sell personal information or use health data for advertising, and we do not share health data with data brokers.
  • You can withdraw AI consent in Settings; AI features require consent to operate.

5. Accuracy, citations & clinical oversight

Vero is an educational organizer — not a diagnostic system. How we reduce (not eliminate) inaccurate or overconfident answers:

  • Source grounding: when explaining labs and health topics, the assistant is instructed to cite allowlisted authoritative sources (such as MedlinePlus, NIH, and other medical authorities) when applicable, so you can open the underlying reference.
  • Physician-informed quality review: board-certified physicians periodically review sampled, de-identified outputs and evaluation results to spot recurring accuracy and safety issues. Physicians do not review every user response. Website educational content is separately medically reviewed — see Medical Reviewers.
  • Known limits: AI can misread a lab image, unit, or reference range; a single value can be meaningless without symptoms, medications, fasting status, and history. Wearable metrics from Apple Health are useful for trends, not diagnosis. Always prefer the range on your own lab report and a clinician's judgment for decisions.

6. Infrastructure & compliance

Vero runs on cloud infrastructure designed for health data workloads. Precisely:

  • We use HIPAA-eligible infrastructure (including Supabase) and maintain Business Associate Agreements (BAAs) for covered services where required.
  • Our primary infrastructure providers maintain SOC 2 Type II certifications. Senddy, Inc. does not currently publish its own SOC 2 report; when we complete an independent audit, we will update this page.
  • Access to production systems is restricted with role-based controls.

HIPAA nuance: using HIPAA-eligible services and BAAs does not mean every consumer interaction with Vero is automatically a HIPAA-covered encounter, or that Senddy is your covered entity for all uses. It means the infrastructure can support HIPAA-regulated workloads when those relationships apply. Read the Privacy Policy for details — and do not treat Vero as a clinical system of record.

7. Data retention & deletion

We retain your data while your account is active. When you delete your account, account-associated health data (profile, chat history, and lab results) is permanently deleted within 30 days. Anonymized, aggregated data may be retained for service improvement. Data required for legal compliance may be retained as mandated by law.

8. Age requirement

Vero is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. By using the app, you represent that you meet this requirement (see our Terms of Service).

Separately, the Apple App Store shows a 13+ content rating for Vero. That badge is Apple's content classification based on its age-rating questionnaire — it is not a manual age setting and it does not change our 18+ eligibility rule.

9. Related pages

10. Contact

Questions about security or privacy:

Senddy, Inc.
privacy@heyvero.ai
legal@heyvero.ai